Plain-language summary (not a substitute for the full policy below): You upload family photos and videos. We use AI technology to analyze them, match faces across your own photos so names get attached to the right person, write a story, generate narration, and render a video. We never sell your personal information or biometric data. You can request deletion of your account and everything tied to it at any time.
| If you're in… | The law that primarily applies | Jump to |
|---|---|---|
| United States | State privacy laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA), BIPA/CUBI/WA biometric laws, COPPA | Section 12 |
| United Kingdom | UK GDPR & the Data Protection Act 2018 | Section 13 |
| European Union / EEA | EU General Data Protection Regulation (GDPR) | Section 13 |
| Canada | PIPEDA (federal), Quebec's Law 25 where applicable | Section 14 |
| Australia | Privacy Act 1988 & the Australian Privacy Principles | Section 15 |
| Anywhere else | The general protections in Sections 1–11 & 17–22 apply to you regardless | Section 16 |
01Who we are & scope of this policy
Videmora, Inc., a Delaware corporation ([registered address on formation]), founded by Md. Robiul Alam and Joy Das ("Videmora," "Company," "we," "us," or "our"), operates the Videmora website, application, and related services (collectively, the "Service"). This Privacy Policy describes how we collect, use, disclose, and safeguard personal information when you use the Service, and the rights available to you depending on where you live. Our primary markets are the United States, United Kingdom, Australia, and Canada, so Sections 12–15 address those jurisdictions specifically; Section 16 covers everyone else.
This Policy applies to all visitors, registered users, and other individuals who access the Service ("you," "user"). It does not apply to third-party websites, products, or services linked to or integrated with the Service, which are governed by their own privacy policies.
If you do not agree with this Policy, please discontinue use of the Service.
02Definitions
- "Personal Information" / "Personal Data" means information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with an identified or identifiable individual — this Policy uses "Personal Information" throughout to mean both terms interchangeably, matching whichever term the law of your jurisdiction uses.
- "Biometric Identifier" / "Biometric Information" means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, and any information based on such an identifier used to identify an individual — this includes "special category data" and "sensitive information" as those terms are used under GDPR and the Australian Privacy Act, respectively.
- "Content" means any photo, video, text, or other material you upload to, or generate through, the Service.
- "Service Provider" / "Processor" means a third party that processes Personal Information on our behalf and under our instructions.
- "Controller" (EU/UK terminology) means the entity that determines the purposes and means of processing Personal Information — Videmora acts as the Controller for the Personal Information described in this Policy.
03Information we collect
3.1 Information you provide directly
| Category | Examples |
|---|---|
| Account & identity data | Name, email address, authentication credentials (password stored as a salted cryptographic hash, never in plaintext) |
| Uploaded Content | Photos and videos you upload, and embedded file metadata (timestamp, device model, GPS coordinates if present) |
| People & relationship data | Names and relationship labels you assign to individuals appearing in your Content |
| Payment & billing data | Handled by our third-party payment processor once payment processing is live; Videmora does not receive or store full payment card numbers. [payment processing not yet active as of this version — this Policy will be updated with the specific processor's name before checkout goes live] |
| Communications | Support requests, survey responses, correspondence you send us |
3.2 Information collected automatically
| Category | Examples |
|---|---|
| Device & usage data | IP address, browser type/version, operating system, device identifiers, referring URLs, pages viewed, timestamps |
| Cookies & similar technologies | See our separate Cookie Policy |
| Diagnostic & error data | Crash logs, performance metrics, error reports |
3.3 Information generated through AI processing of your Content
| Category | Examples |
|---|---|
| Derived scene/content analysis | AI-generated descriptions of scenes, objects, estimated emotional tone |
| Facial detection data | Bounding-box coordinates identifying where faces appear within an image |
| Biometric matching data | See Section 7 — treated as sensitive Personal Information under this Policy and applicable law everywhere we operate |
| Generated Output | AI-written narrative text, synthesized narration audio, rendered video files |
04Legal bases for processing (relevant to UK/EU users, and good practice everywhere)
Where UK GDPR or EU GDPR applies to you, we rely on the following legal bases to process your Personal Information:
- Performance of a contract — processing your uploaded Content to generate your memory film, since that's the service you've asked us to perform.
- Consent — for biometric facial-matching (Section 7) and for non-essential cookies (see our Cookie Policy), both of which require your affirmative opt-in under GDPR's treatment of special category data and the UK's Privacy and Electronic Communications Regulations (PECR). You may withdraw consent at any time, as described in Sections 7 and 17, without affecting the lawfulness of processing carried out before withdrawal.
- Legitimate interests — for security, fraud prevention, and service improvement, balanced against your rights and only where our interest is not overridden by your interests or fundamental rights.
- Legal obligation — where we must retain or disclose information to comply with applicable law (e.g., tax recordkeeping, responding to lawful requests from authorities).
05AI processing & automated decision-making
The Service relies substantially on artificial intelligence technology, including image analysis technology, large language model text-generation technology, voice synthesis technology, and biometric facial-matching technology. This processing is automated: no human reviews your Content as a routine part of providing the Service, other than automated moderation and, where necessary, limited human review to investigate abuse reports, security incidents, or legal obligations.
This automated processing determines how faces are matched within your own uploaded photos and how narrative text is generated — it does not make any decision producing a legal or similarly significant effect concerning you (it does not determine eligibility for credit, employment, housing, insurance, or similar outcomes). Under UK/EU GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces such effects; because our processing does not produce such effects, Article 22's core protection is not triggered, but you may still contact us under Section 17 with questions about how this processing works.
06How information is shared
We do not sell your Personal Information, anywhere. We share information only in the following circumstances:
6.1 Service providers, by functional category
| Functional category | Purpose | Data involved |
|---|---|---|
| AI image & content analysis technology | Analyzing uploaded photos | Uploaded photos |
| AI language generation technology | Generating narrative story text | Content analysis output, names/relationships you provide |
| AI voice synthesis technology | Generating spoken narration | Generated story text |
| Biometric facial-matching technology | Matching the same face across photos within your own session | Uploaded photos, derived facial geometry data — see Section 7 |
| Cloud video rendering infrastructure | Assembling photos, narration, and text into a finished video | Photos, narration audio, story text |
| Cloud database & file storage infrastructure | Storing account, content, and application data | All categories described in Section 3 |
| Application hosting infrastructure | Serving the website and application | All data in transit through the Service |
| Payment processing partner | Processing purchases and managing billing, once live | Payment and billing details only [processor to be named here once integrated] |
We describe most service providers by functional category rather than naming specific commercial vendors in this public-facing document, to avoid giving competitors a roadmap to our technology stack. A complete list of current sub-processors, including specific vendor names and, where applicable, their Standard Contractual Clauses or other transfer safeguards, is available upon written request to the contact in Section 22, and will be provided to any user or regulator entitled to it under applicable law.
6.2 Legal & safety disclosures
We may disclose information where required to comply with valid legal process, to enforce our Terms of Service, to detect or prevent fraud or security incidents, to protect the rights, property, or safety of Videmora, our users, or the public, or in connection with a merger, acquisition, financing, or sale of assets (requiring the successor to honor the commitments in this Policy).
6.3 With your direction
When you generate a shareable link, the story text and video become accessible to anyone with the link, until you disable sharing.
07Biometric information
The Service uses biometric facial-matching technology to detect faces in your uploaded photos and generate a mathematical representation of facial geometry (a "faceprint") so the same person can be recognized and consistently named across multiple photos within your own session. This is regulated as sensitive/special-category data under multiple frameworks, including the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act, Washington's biometric privacy law, UK/EU GDPR Article 9 (special category data — biometric data used for the purpose of uniquely identifying a natural person), and the Australian Privacy Act's treatment of biometric information as "sensitive information" under Australian Privacy Principle 3.
Our written biometric data policy
Purpose: collected solely to provide the in-session face-matching feature described above.
No sale or profit: we do not sell, lease, trade, or otherwise profit from biometric identifiers, and we do not disclose biometric data to any party other than the processor strictly necessary to provide the feature, except where required by valid legal process.
Retention: we permanently destroy biometric identifiers when the initial purpose has been satisfied, or within three (3) years of your last interaction with the Service, whichever is first. On a verified account deletion request, we remove associated facial-matching records from the underlying biometric matching system, not merely from our own database.
Legal basis / consent: where GDPR applies, we rely on your explicit consent (GDPR Art. 9(2)(a)) for this processing, given through your acceptance of this Policy and your affirmative act of using the naming/tagging feature; where BIPA and similar US laws apply, this constitutes the informed written consent those statutes require. In every jurisdiction, you may withdraw consent at any time by discontinuing use of the naming feature and requesting deletion under Section 17 — this will not affect processing already lawfully carried out.
08Information about people who aren't account holders
Family photographs routinely include people who have never created a Videmora account. When you upload a photo, you represent and warrant that you possess the necessary rights and consent — including, where a depicted individual is a minor, consent from that minor's parent or legal guardian — to have that photo processed as described in this Policy, including biometric facial-matching under Section 7. You, the uploading account holder, are solely responsible for obtaining that consent.
If you are an individual who appears in a photo uploaded by another user and wish to exercise a privacy right described in Sections 12–17 with respect to your own data, contact us at Section 22. We will process such requests in accordance with applicable law, which may require verification of your identity and relationship to the relevant account or Content.
09Children's privacy
The Service is intended for users at least 18 years old, and account registration is restricted accordingly. This is intentionally higher than the minimum age of digital consent in most of our primary markets (commonly 13–16 depending on jurisdiction) because of the sensitivity of biometric processing involved. We do not knowingly collect Personal Information directly from a child for purposes of COPPA (US), the UK's Age Appropriate Design Code, or equivalent frameworks; all account holders are adults, and all uploads are made by an adult rather than collected directly from a child.
Because Videmora is a family-memory product, Content will routinely depict minors as uploaded by a parent, legal guardian, or other authorized adult. If we become aware that data about a minor was uploaded without appropriate authorization, we will investigate and, where warranted, delete the relevant data. Parents or guardians who believe their child's information has been collected inappropriately may contact us using Section 22.
10Data retention schedule
| Data category | Retention period |
|---|---|
| Active account & Content data | Retained for as long as the account remains active |
| Biometric identifiers | Destroyed when the purpose is satisfied, or within 3 years of your last interaction, whichever is first |
| Deleted account — primary systems | Removed within 30 days of a verified deletion request |
| Deleted account — backups | Purged within 90 days of a verified deletion request |
| Billing & transaction records | Retained independently of account deletion for 7 years, as required for tax and financial recordkeeping (once payment processing is live) |
| Security & fraud-prevention logs | Up to 12 months, or longer to investigate an active incident |
| Inactive accounts | We may notify you and deactivate/delete after 24 months of continuous inactivity |
11Security
We implement administrative, technical, and physical safeguards designed to protect Personal Information, including encryption in transit (TLS), encryption at rest where supported by our infrastructure providers, database-level access controls restricting each account to its own data, and restricted internal access to production systems on a need-to-know basis. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12United States
12.1 California (CCPA/CPRA)
California residents have rights to know, correct, delete, and port their Personal Information; to opt out of sale or sharing (we do not sell or share, and have not in the preceding 12 months); to limit use of sensitive Personal Information including biometric data; to opt out of certain automated-decision profiling (see Section 5); to non-discrimination for exercising these rights; and to appeal a denied request (Section 17). California residents may designate an authorized agent to submit a request, subject to our ability to verify the agent's authority.
12.2 Virginia, Colorado, Connecticut & Utah
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA) have rights to access, correct, delete, and port their Personal Information, and to opt out of targeted advertising, sale, and certain profiling. We do not engage in targeted advertising or sell Personal Information. Where these statutes grant an appeal right, see Section 17.
12.3 Illinois, Texas & Washington (biometric-specific)
See Section 7 for our written biometric data policy, applicable to residents of these states and to anyone whose biometric information we process.
12.4 Nevada
Nevada residents may direct us not to sell covered information; as stated above, we do not sell Personal Information.
13United Kingdom & European Union
If UK GDPR or EU GDPR applies to you, in addition to the rest of this Policy, you have the following rights, which you may exercise via Section 17:
- Right of access — obtain confirmation of whether we process your data and a copy of it
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten") — request deletion, subject to the retention exceptions in Section 10
- Right to restrict processing — limit how we use your data in certain circumstances
- Right to data portability — receive your data in a structured, commonly-used, machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent at any time, for processing based on consent (Sections 4 and 7), without affecting the lawfulness of prior processing
- Right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO); in the EU, your local data protection authority
GDPR Art. 27 / UK GDPR Art. 27If we process personal data of individuals in the UK or EU in connection with offering the Service to them, and that processing is not merely occasional or low-risk, we may be required to appoint a UK and/or EU representative. [Founders to assess based on actual UK/EU user volume and appoint a representative if the exemption for occasional, low-risk processing does not apply; representative contact details to be added here once appointed.]
14Canada
If you're in Canada, the federal Personal Information Protection and Electronic Documents Act (PIPEDA) applies to our handling of your Personal Information, alongside applicable provincial law (for example, Quebec's Law 25, which applies additional requirements for Quebec residents including a right to data portability and rules on automated decision-making). You have the right to access and request correction of your Personal Information, to withdraw consent (subject to legal or contractual restrictions), and to file a complaint with the Office of the Privacy Commissioner of Canada (or, for Quebec residents, the Commission d'accès à l'information).
15Australia
If you're in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply. Biometric information is "sensitive information" under APP 3, requiring your consent to collect except in limited circumstances — consistent with the consent basis described in Section 7. You have the right to access and seek correction of your Personal Information under APP 12–13, and to complain to us directly (Section 22) or, if unresolved, to the Office of the Australian Information Commissioner (OAIC). Consistent with the Notifiable Data Breaches (NDB) scheme, we will notify the OAIC and affected individuals as soon as practicable if an "eligible data breach" occurs, per Section 20.
16Other jurisdictions
If you're located somewhere not specifically addressed in Sections 12–15, the general protections described throughout this Policy — our commitment not to sell your data, our biometric data safeguards (Section 7), our retention schedule (Section 10), and our security practices (Section 11) — apply to you regardless of your location. Contact us via Section 22 with any question about how local law interacts with our practices, and we will respond in good faith even where a formal statutory right may not apply in your jurisdiction.
17How to exercise your rights & our response timeframes
- How to submit a request: email the address in Section 22, or use the account deletion / data export tool within the Service where available.
- Verification: we will take reasonable steps to verify your identity before acting on a request. We will not request more information than reasonably necessary for verification.
- US response time: we confirm receipt within 10 business days and substantively respond within 45 calendar days, extendable by one additional 45-day period with notice to you.
- UK/EU response time: we respond within one (1) month of receipt, extendable by a further two months for complex or numerous requests, with notice to you within the first month explaining the extension, consistent with GDPR Article 12.
- Canada & Australia response time: we respond "as soon as reasonably possible," and in any case within 30 days, consistent with common practice under PIPEDA and the APPs.
- Appeal (US state laws): if we decline a request, you may appeal within 30 days; we respond to appeals within 45 days, and if we uphold the denial, we will explain why and, where required, provide information on how to complain to the applicable regulator.
- No fee: we do not charge a fee to process a request unless it is excessive, repetitive, or manifestly unfounded, in which case we will explain the basis for any fee before proceeding, or may refuse the request as permitted under applicable law.
19International data transfers
Videmora, Inc. is a Delaware corporation, and our infrastructure and service providers operate primarily in the United States. If you access the Service from the UK, EU, Canada, Australia, or elsewhere, your information will be transferred to and processed in the United States, where data protection laws differ from those of your home jurisdiction.
Where UK or EU GDPR requires a specific transfer safeguard for this to be lawful, we rely on one or more of: the European Commission's Standard Contractual Clauses (SCCs), the UK's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, or another legally recognized transfer mechanism, incorporated into our agreements with the relevant service providers. [Founders: confirm and document which specific mechanism is in place with each provider once sub-processor agreements are finalized; details available on request per Section 6.]
20Security incident notification
If we become aware of a security incident compromising the confidentiality, integrity, or availability of your Personal Information in a manner requiring notification, we will notify affected individuals and relevant regulators consistent with the specific timing required in your jurisdiction:
- UK/EU: notification to the ICO or relevant supervisory authority without undue delay, and where feasible, within 72 hours of becoming aware, per GDPR Article 33.
- Australia: notification to the OAIC and affected individuals "as soon as practicable" for an eligible data breach, per the Notifiable Data Breaches scheme.
- Canada: notification to the Privacy Commissioner and affected individuals "as soon as feasible" for a breach posing a real risk of significant harm, per PIPEDA.
- United States: notification consistent with the applicable state breach-notification statute, commonly "without unreasonable delay" up to a maximum of 30–60 days depending on the state.
21Changes to this policy
We may update this Policy to reflect changes in our practices or applicable law. We will update the effective date above, and for material changes, provide more prominent notice (such as an in-app notification or email) at least 10 days before the change takes effect where reasonably practicable. Continued use of the Service after a change takes effect constitutes acceptance.
22Contact us & representatives
Videmora, Inc., a Delaware corporation
Founders: Md. Robiul Alam, Joy Das
Registered agent for service of process (US): [registered agent name & Delaware address on formation]
UK representative (Art. 27, if applicable): [to be appointed if required — see Section 13]
EU representative (Art. 27, if applicable): [to be appointed if required — see Section 13]
Privacy inquiries: [privacy@videmora.com]
General inquiries: [hello@videmora.com]
Videmora, Inc. · This document is an AI-assisted draft template prepared for founder review and has not been reviewed by a licensed attorney. Replace all bracketed placeholders — particularly Sections 7, 13, and 19 — and obtain legal review before publishing, especially before actively marketing to UK/EU users given the Article 27 representative question.